Today split into two stories that don't touch each other but rhyme: an active supply-chain worm spreading through the npm registry, and a security-research backlog landing on AI-agent-orchestration tooling in one coordinated dump.
The worm — Aikido ties it to the Shai-Hulud lineage, BleepingComputer calls it ChainDrop — compromised the keyv maintainer's GitHub account this morning and republished itself into downstream packages using stolen npm tokens, planting hooks aimed specifically at Claude Code and VS Code credentials; counts moved from 353 poisoned versions to 868+ packages by afternoon. Flowise absorbed 23 CVEs across two disclosure waves today — CSVAgent alone produced five independent RCE paths, and an unauthenticated OAuth2 credential-refresh endpoint leaked tokens twice, in two separate advisories. Open WebUI shipped six of its own in the same window, including an OAuth account-takeover bug, two stored-XSS paths, and two SSRF variants reaching internal services and cloud metadata, while CISA added three fresh KEV entries, including a third Langflow RCE catalogued in five weeks. The one bright spot: Socket's package scanning is now a one-click add inside AWS Security Hub, lowering the bar for orgs without supply-chain scanning wired into CI yet.
→ Operational priority for the night freeze keyv, cacheable, and their dependents, and audit for the planted Claude Code/VS Code hooks first; then pull CSVAgent and any public overrideConfig-reachable Flowise chatflows offline until every one of today's 23 patches is confirmed applied.